VLAN Broadcast Restriction via Group Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless networks, access points face processing burdens due to multiple address translations for broadcast traffic, and existing techniques require static VLAN associations, which are not feasible in dynamic Enterprise Wireless LAN environments.
Innovation Solution
Implementing a VLAN by sending a unique group key to stations, encrypting frames addressed to the VLAN, and broadcasting them, allowing only keyed stations to decrypt, thereby reducing processing load and enabling dynamic VLAN membership without hard handoffs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an access point maintains a VLAN table and performs multiple address translations for broadcast traffic, then VLAN membership can be dynamically associated based on user policy, but the processing load on the access point increases and traffic throughput slows down
Solution Approach 1:
The patent segments VLAN traffic handling by separating broadcast/multicast frame processing from unicast frame processing. The access point encrypts broadcast and multicast frames with VLAN-specific group keys before transmission, while unicast frames continue to use traditional address translation methods. This segmentation allows dynamic VLAN association to be maintained without imposing address translation overhead on all traffic types, thereby preserving traffic throughput while enabling adaptability.
2Productivity
If an access point is dedicated to a particular VLAN with unified membership, then the access point can simply broadcast VLAN messages without additional processing, but the access point cannot serve other VLANs and requires static association
Solution Approach 1:
The patent enables a single access point to serve multiple VLANs simultaneously by implementing multi-functionality. The access point maintains associations with multiple VLANs and encrypts broadcast frames with different group keys corresponding to different VLANs. This allows the access point to efficiently broadcast to multiple VLANs without requiring dedicated access points for each VLAN, thereby maintaining both broadcast efficiency and VLAN flexibility.
3Adaptability or versatility
If broadcast frames are sent to all stations associated with a BSSID, then VLAN restriction is achieved, but stations without the appropriate group key can potentially access VLAN traffic
Solution Approach 1:
The patent applies local quality by encrypting broadcast and multicast frames with VLAN-specific group keys. Each VLAN has its own encryption key, and only stations that possess the corresponding group key can decrypt and access the traffic. This ensures that while broadcast frames are sent to all stations associated with the BSSID for efficient delivery, only the intended VLAN members can actually read the content, thereby achieving both VLAN restriction and security.
Data Source
AI summary
Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.


